Security & Compliance
Built to be trusted with your students’ data.
GDPR-compliant, UK/EU-hosted, safeguarding-first, and accessible by design.
The essentials
What your IT and data protection leads will ask
Everything below is designed to be forwarded to procurement without further translation.
Data protection & GDPR
UK GDPR and EU GDPR aligned, with a data-processing agreement, records of processing and a named DPO contact.
Where your data lives
Hosted in the UK/EU with documented residency. Regional hosting available for international schools on request.
Safeguarding & child safety
Age-appropriate AI, monitored communities, keyword flagging and teacher controls across every student-facing surface.
Access & single sign-on
SSO via Microsoft Entra ID and Google Workspace, role-based permissions and a full administrative audit trail.
Accessibility
Targeting WCAG 2.2 AA across product and marketing site, with a published accessibility statement.
Uptime & reliability
99.9% uptime target, monitored around the clock, with a public status page and incident communications.
AI responsibility
No training on your school’s data. Copilot answers are grounded in your course material, not the open internet.
Certifications & policies
Downloadable security pack: policies, sub-processor list, penetration-test summary and compliance posture.
For procurement
Request the security pack
Policies, sub-processor list, penetration-test summary, data-processing agreement and accessibility statement — in one download, so your review starts today rather than after three emails.
In the pack
- Information security policy
- Data-processing agreement (DPA) template
- Sub-processor list and locations
- Penetration-test executive summary
- Business continuity & incident response
- Accessibility conformance statement
Exact certifications and residency commitments to be confirmed before launch.
FAQ
Security & data protection questions
In the UK/EU by default, with documented residency. International schools can discuss regional hosting during procurement.
No. Course content and student conversations are never used for model training, and this is written into the data-processing agreement rather than only stated on a website.
Yes — request the security pack below. It includes policies, the sub-processor list, a penetration-test summary and our data-processing agreement.
Flagged content routes to your named safeguarding lead with full context. Escalation paths, retention and reporting are configured to your school’s policy.
We target WCAG 2.2 AA across the product and this marketing site, and publish an accessibility statement schools can reference in their own compliance reporting.
You can export your content and records at any time. On termination, data is deleted according to the schedule in the agreement.